ZeroHour
Vendor

Automattic

6 mentions in 7 days · 9 in 30 days · 10 total · first seen · last

Timeline

Automattic’s Matt Mullenweg Claims He’s Back 'In Control'

Automattic CEO Matt Mullenweg says he is back in control of the company 48 hours after the board placed him on leave.

Automattic co-founder Matt Mullenweg announced in a company-wide Slack channel that the board is back in agreement and he is in control, less than 48 hours after announcing he had been placed on leave. CFO Mark Davies, who was set to act as interim CEO, had his Slack account deactivated. The board has communicated nothing beyond Wednesday's Slack message, and Mullenweg's follow-up blog post addressed buying a tugboat, not the leadership confusion.

404 Media · 4d agoOther 7 sources

Matt Mullenweg tells Automattic staff in Slack he's back in control after ouster

Automattic founder Matt Mullenweg says via Slack he has regained CEO control days after the board ousted him and made CFO Mark Davies interim CEO.

Automattic's board voted earlier this week to place founder Matt Mullenweg on paid leave and named CFO Mark Davies interim CEO, confirmed at the time by a company spokesperson. On Friday, Mullenweg posted in Automattic's Slack that the board was 'back in agreement' and that he was in control; employee sources said Davies' Slack account was deactivated. Mullenweg has publicly suggested Silver Lake, majority owner of WP Engine — which is suing Mullenweg and Automattic — was involved in the ouster. Automattic had not formally confirmed his claim and the situation remains fluid.

Hacker News · securityupdated · 4d agofirst · 4d agoOther 7 sourcesHN 44↑ · 17 comments

WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites

WordPress.org now auto-blocks plugin updates flagged by AI review after a backdoor incident, adding a supply-chain gate for millions of sites.

Since June 5, 2026, every WordPress.org plugin and theme release passes a mandatory six-hour cooldown while multiple AI models and Jetpack Scan analyze code changes and produce a consolidated security score; releases above the risk threshold are blocked automatically. The change followed a July 28, 2026 incident where a backdoor was pushed into a plugin with roughly 20,000 active installs, which Wordfence flagged and the Plugins Team pulled 26 minutes later before distribution. Authors are notified of blocking findings and can republish corrected releases or appeal false positives to the Plugins Team.

Cyber Security Newsupdated · 4d agofirst · 5d agoTools 7 sources

WordPress adds automated security checks to block risky plugin releases

WordPress.org now automatically security-reviews every plugin release and blocks high-risk updates before distribution to millions of sites.

The WordPress Official Plugin Repository Team launched an automated security review that scores each plugin and theme release during a six-hour cooldown, combining analysis from several AI models and Jetpack Scan, and automatically blocks releases deemed high risk. The change followed a July 28 detection of a backdoor committed to a release of a plugin with roughly 20,000 active installations; the release was withheld and the plugin closed for downloads 26 minutes after Wordfence notified the team. Blocked authors must fix findings and publish a new release scoring below the blocking threshold, or appeal to the Plugins Team.

Help Net Securityupdated · 4d agofirst · 5d agoTools 7 sources

Automattic's board forces CEO Matt Mullenweg into leave of absence

Automattic's board voted to place CEO Matt Mullenweg on paid leave against his will, naming CFO Mark Davies interim CEO of WordPress's parent company.

Automattic's board voted to put founder and CEO Matt Mullenweg on paid leave against his will, with CFO Mark Davies appointed interim CEO; Mullenweg remains on the board. The move follows years of turmoil, including a protracted legal battle with WP Engine, a 2024 ultimatum in which 159 employees took severance, and a 16% staff layoff in April 2025. WordPress.org's executive director said the open-source WordPress project and its teams continue as planned and are not impacted. Automattic also owns Tumblr, WooCommerce, and Pocket Casts.

Hacker News · securityupdated · 4d agofirst · 6d agoOther 7 sourcesHN 23↑ · 99 comments

Automattic CEO Matt Mullenweg Put on 'Leave of Absence'

Automattic's board placed CEO Matt Mullenweg on paid leave of absence, naming CFO Mark Davies interim CEO of the WordPress and Tumblr owner.

Automattic board members voted to put founder and CEO Matt Mullenweg on paid leave of absence, with CFO Mark Davies appointed interim CEO. Mullenweg claims the move was made 'behind his back' and that he was denied time to have the resolution reviewed by independent legal counsel. The company owns WordPress, Tumblr and Pocket Casts, and Mullenweg has been engaged in a divisive legal battle with WP Engine. Davies told employees nothing will change and that Mullenweg remains a board member.

404 Mediaupdated · 4d agofirst · 6d agoOther 7 sources

404 Media

404 Media homepage roundup: WordPress CEO Matt Mullenweg put on leave, first Take It Down Act sentence of 15 years, and DHS predictive policing revelations.

The 404 Media feed aggregates stories including Automattic board members voting WordPress co-founder Matt Mullenweg onto a leave of absence, and James Strahler receiving 15 years under the Take It Down Act for real and AI-generated sexually explicit images plus threats. It also reports a secretive DHS Border Patrol predictive policing unit that analyzes Americans' financial data and has local police pull people over with no suspected crime. Additional items cover Channel 5 sharing subscriber emails with Hunter Biden despite its privacy policy, and a man's death after emotional reliance on ChatGPT.

404 Media · 8d agoOther

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Attackers are actively exploiting critical file-upload flaw CVE-2026-32475 in Elementor Pro, hacking WordPress sites; Defiant has blocked over 190,000 exploit attempts since patching.

Defiant warns that attackers are exploiting CVE-2026-32475 (CVSS 9.8), an unauthenticated arbitrary file upload flaw in the Elementor Pro WordPress plugin's form submission handling, which affects all versions up to 4.2.1 and was patched in version 4.2.2 on August 19. Exploitation began immediately after the fix shipped, with Defiant blocking over 190,000 exploit attempts to date; roughly two-thirds of Elementor's 10 million installations still ran a vulnerable version as of September 4. Successful exploitation writes attacker-controlled PHP files to /wp-content/uploads/elementor/forms/ and can lead to full site compromise; administrators should check that directory for PHP files and review requests to /wp-admin/admin-ajax.php.

SecurityWeek · 10d agoExploit / PoC in the wildCVE-2026-32475

Elementor Pro RCE Flaw Under Active Attack

A critical Elementor Pro Forms module flaw allowing unauthenticated file uploads is under active attack against widely used WordPress sites.

A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload arbitrary files through the plugin's Forms module. The SOCRadar report indicates the flaw is being actively exploited in the wild. No CVE identifier was provided in the available text.

SOCRadar · 11d agoExploit / PoC in the wild

[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

An unauthenticated arbitrary file upload exploit was released for a WooCommerce component version 1.5.0, risking site compromise.

Exploit-DB published exploit #52642 targeting WooCommerce 1.5.0. The flaw allows unauthenticated arbitrary file uploads, which can lead to remote code execution on affected web servers. The disclosure text does not report exploitation in the wild.

Exploit-DB · Aug 17, 2026Exploit / PoC

Related CVEs

  • Unauthenticated PHP File Upload (RCE) in Elementor Pro WordPress Plugin
    Elementor Pro, the paid add-on to the widely used Elementor page builder for WordPress, is affected by an unrestricted upload of files with dangerous types (CWE-434) that can be triggered by unauthenticated attackers. An attacker sends a crafted upload request to the plugin's vulnerable endpoint and can upload a dangerous file — notably a PHP file — which the web server then executes, yielding remote code execution on the hosting account. The critical 9.0 CVSS score with scope change (S:C) and high impact across confidentiality, integrity and availability reflects that code execution lets an attacker take over the site, plant backdoors, modify content and potentially affect the underlying host. All Elementor Pro releases up to and including 4.2.1 are affected, meaning every site that has not yet updated to a fixed version is in scope. The flaw is not yet listed in CISA KEV and no public proof-of-concept is cataloged, and EPSS assigns a 2.4% 30-day exploitation probability (83rd percentile), but news reports already document hundreds of thousands of exploit attempts against Elementor Pro and Super Forms RCE flaws, so it should be treated as exploited in the wild.
    · Elementor Pro (WordPress plugin) All versions from n/a through 4.2.1 (i.e., every release up to and including 4.2.1)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.